ssh authorized_keys bypasses security?

From: Jem Berkes (jb2002_padding_@pc9.org)
Date: 07/08/02


From: Jem Berkes <jb2002_padding_@pc9.org>
Date: Mon, 08 Jul 2002 16:03:24 GMT

Perhaps somebody can help clarify something for me, regarding OpenSSH's
authorized_keys file. There are several PCs on my network which back up
their data to one linux host using rsync over ssh. On each client I used
ssh-keygen to produce a key pair, and inserted the public key of each into
the .ssh/authorized_keys file on a certain linux account.

So the net result is that several hosts gain access to one account on the
server, and none of them need to know the account password. This seems to
be completely bypassing the linux server's user authentication system --
are there additional risks resulting from this that I haven't seen?

-- 
Jem Berkes
Student IEEE (Canada)

http://www.pc-tools.net/ Windows, Linux & UNIX software



Relevant Pages

  • Squid
    ... Instant messenger on Linux ... Time difference between Win98 and Fedora ... Detecting inactive accounts ... > I'm trying to write a script that will detect if an account ...
    (Fedora)
  • Re: GLIDER
    ... maybe they just scan ur HD for Glider? ... You will find that during the last glider-banwave, a lot of Linux users ... logs and revoke a ban if it was unjustified. ... their accounts back and the time lost credited to their account, ...
    (alt.games.warcraft)
  • RE: SSO on linux
    ... We were about to start looking at MS Services for Unix when I was informed by a contact of mine that it is possible to do what you suggest without it. ... account required /lib/security/$ISA/pam_unix.so ... guides on implementing 'Single Sign On' on a linux server using Kerberos, ... This email has been scanned for all viruses by the MessageLabs Email ...
    (Focus-Linux)
  • Re: stability help needed
    ... You might take into account to not post in html in any linux related mailings ... > do the post install update. ...
    (Fedora)
  • Re: Got my original Steam account back!
    ... Linux, ... I tested Steam via Wine and found that while many ... Valve games sorta-worked, they either had annoying issues (eg. GoldSrc ... access to an existing account, ...
    (comp.sys.ibm.pc.games.action)